REDHAT-BUG-2404426: Medium severity Moodle Moodle vulnerability
Insufficient handling of access control checks in the courseoutputfragmentcourseoverview() function allows information about restricted courses to be returned to users lacking proper permissions. An attacker with a valid Moodle account could exploit this to view metadata about inaccessible courses.
Versions affected: 5.0 to 5.0.2 Versions fixed: 5.0.3
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2404426?
The severity of REDHAT-BUG-2404426 is considered critical due to the potential exposure of restricted course information.
How do I fix REDHAT-BUG-2404426?
To fix REDHAT-BUG-2404426, it is recommended to update your Moodle version to at least 5.0.3, where the vulnerability is addressed.
What type of vulnerability is REDHAT-BUG-2404426?
REDHAT-BUG-2404426 is an access control vulnerability that allows unauthorized access to restricted course metadata.
Who is affected by REDHAT-BUG-2404426?
Users with valid Moodle accounts who lack proper permissions to view restricted courses are at risk from REDHAT-BUG-2404426.
Can REDHAT-BUG-2404426 be exploited remotely?
Yes, an attacker can exploit REDHAT-BUG-2404426 remotely if they have a valid Moodle account.